Question

What is the difference between a linter and a formatter?

Vault Verified
Curated Intelligence
Definitive Source
Answer

A formatter changes how code looks. A linter analyses what code does and flags problems. They are complementary, and confusing them leads to teams configuring one to do the other's job badly.

A formatter rewrites code to a consistent style — indentation, line length, quote style, bracket placement, trailing commas. It makes no judgement about correctness and changes no behaviour.

The modern generation are deliberately opinionated with few options. Prettier, Black, gofmt and rustfmt all take this position, and the reasoning is sound: the value is in ending the argument, not in the specific choices. A team debating brace placement is wasting time on something with no correct answer, and a tool that decides removes the discussion entirely.

Run it automatically — on save, and in a pre-commit hook — so formatting never appears in review.

A linter performs static analysis, examining code without running it, and reports:

Likely bugs — unused variables, unreachable code, comparing incompatible types, missing awaits, promises not handled.

Suspicious patterns — assignment inside a condition, loose equality, shadowed variables.

Security issues — dangerous functions, injection risks.

Maintainability concerns — excessive complexity, overly long functions.

Project conventions — enforcing agreed patterns.

Some linters can auto-fix a subset of findings, which blurs the line, but the purpose remains analysis rather than presentation.

Why the distinction matters practically. Using a linter for stylistic rules produces noisy output where genuine bugs are lost among complaints about spacing. Letting a formatter own style leaves the linter reporting only things worth reading — which is what makes people actually read it.

Related tools: a type checker verifies type correctness, and is far more powerful than lint rules for the same problems; and a static application security testing tool goes deeper on security.

Run all of them in CI, so standards are enforced rather than requested.

Related Questions